URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: link.icloudcowboy.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-06-15 06:37:02 UTC
Total malware sites :1
A record(s) observed :2

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-06-15 06:37:04 195.22.152.118vaga99999938.example.comNot listedAS47196 Garant-Park-Internet- RUno
2020-06-15 06:37:04 31.41.44.196free.cishost.ruNot listedAS56577 ASRELINK- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-06-15 06:37:04http://link.icloudcowboy.com/setup.exeOfflinegeofenced Gozi ext ITA ursnif ext JAMESWT_MHT

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-06-21 19:30:116371f0247fc473f4a62dc80511eb8e67ef1cdcaf97109227d64541f8957402bcexe  
2020-06-20 13:40:054a4972c000b3d822d99c77e77c3608f8da72fb3ea73e8a6cc2ca2d1c68f8d0f8exe  
2020-06-16 04:27:376a473e38f47d6ec7d3dcdcd4ccd8e1d8d9e388d1b8b169011bf89c273327d5a3exeGozi
2020-06-16 03:53:1882d62675daaa3a85f419c86bf5221e55e1e26f830fc711dcafc574d567afa634exe Gozi
2020-06-16 02:11:352fde4d251ebdd918124280abfc53ab05b42b7b0bf51cd5409dab20f7bd26f657exe Gozi
2020-06-16 00:41:579aaf4cf4d3f24b75f82f3200c9c1172f68021845707b524318b78d925f49adc2exe Gozi
2020-06-15 23:27:2466d93e44b4091c24fc2b319efd9eabe43932ab85e32a08fe87d9428ea0b71aedexe Gozi
2020-06-15 22:29:2954f3af6816ec5a9454043a657621985670b043da6a1fbee8c462e3ecc3edd39fexe Gozi
2020-06-15 21:08:34d6ad700c9b42767e90bd7e552434f00c5945b82ff5d4185223f64347def4b8b4exe Gozi
2020-06-15 19:57:53500f87d09dc1e2a1c245247d2d14f5897eddb2857c3abe67aa0600527c4dc9d3exe Gozi
2020-06-15 19:31:546faa3110db3a2b6d2d2b377a519fda1e6818284f3c25a1ef379f3e1f6634cea6exe Gozi
2020-06-15 17:33:432cd12c96677db4e592b2ec01eccb0ba9a51b061498a36441f422de372d13da4fexe Gozi
2020-06-15 15:26:0029eba6e40bd67080024f220aea3bfc15b532c4e4d0fdf0c802689496f2744f32exe Gozi
2020-06-15 14:39:589f28fb3c7a60d8cf4b320887f25ed84417ec984d7e255910ed8127e23e7b3b9eexe Gozi
2020-06-15 14:39:469f28fb3c7a60d8cf4b320887f25ed84417ec984d7e255910ed8127e23e7b3b9eexe Gozi
2020-06-15 12:39:43b57950321a93e2d2930e926087e1945e3bbfa78a4265bdc4bf888afcf781a27dexe Gozi